How to Block Certain Source Addresses from Accessing Backend Service Nodes?
CLB supports the firewall function, which can be used as follows:
- Bind the firewall when creating the load balance, or go to the “Internet Firewall” tab page in the CLB details page to bind the firewall.
Please note:
- In the process of configuring the firewall, if it is necessary to restrict the whitelist/blacklist of a certain request proxy mode VServer, you need to configure the allow/deny policy of the corresponding port of the VServer in the firewall. Because the default behavior of the firewall is to refuse, please be sure to add the corresponding source address release rule for the corresponding port of the VServer when configuring the firewall, to avoid affecting the business.